PT-2026-37577 · Linux+1 · Linux Kernel+1

CVE-2026-43237

·

Published

2026-05-06

·

Updated

2026-08-30

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the amdgpu gem va ioctl function where the fence was selected too early and its reference was not managed correctly. This leads to refcount underflows and the use of stale or freed fences, resulting in a use-after-free condition on dma fence. This flaw can cause the system to crash or trigger a kernel panic when updating GPU timelines.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:57251
ALSA-2026:57252
AZL-85884
CVE-2026-43237

Affected Products

Linux Kernel
Rocky Linux